3 ms·
I also cannot believe that this is the 9.9 rated CVE. For comparison, heartbleed was a 7.5. I was awaiting a Total Linux Meltdown at best and a collapse of th
by RGBCube 2y ago
I also cannot believe that this is the 9.9 rated CVE. For comparison, heartbleed was a 7.5. I was awaiting a Total Linux Meltdown at best and a collapse of the world economy at worst with the amount of hyping up and fearmongering that the author did on social media.
- bogantech 2y agoLink to the OP for those that haven't seen it: https://x.com/evilsocket/status/1838169889330135132 https://x.com/evilsocket/status/1838169889330135132 Hyped it up to be some massive thing but it turned out to be a massive nothingbuger for me at least
- RGBCube 2y agoNon-loginwalled link: https://threadreaderapp.com/thread/1838169889330135132.html https://threadreaderapp.com/thread/1838169889330135132.html
- maeln 2y agoIt's always funny to me how cybersecurity always seem to attract people with a ... certain sense of ego.
- evilos 2y agoThey claim to not be a cybersecurity pro
- ChocolateGod 2y ago> pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more. I can think of another reason they got patronised.
- deleted 2y ago[deleted]
- NavinF 2y agoYeah tbh it's not as bad as he claimed. I doubt this is actually rated 9.9: >A remote unauthenticated attacker can silently replace existing printers’ (or install new ones) IPP urls with a malicious one, resulting in arbitrary command execution (on the computer) when a print job is started (from that computer). >WAN / public internet: a remote attacker sends an UDP packet to port 631. No authentication whatsoever. >LAN: a local attacker can spoof zeroconf / mDNS / DNS-SD advertisements (we will talk more about this in the next writeup ) and achieve the same code path leading to RCE. Still, sucks for linux desktop users. Looks like any random device on your wifi/vpn can screw you over
- floren 2y agoOr any malicious user on the airport wifi. The compromise will linger until however many weeks later when you decide to print something...
- bremac 2y agoKeep in mind that you still need send a print job to the fake printer to trigger the exploit. If you send the job to your real printer, nothing happens.
- crote 2y agoThe exploit allows an attacker to overwrite your real printer with their fake printer.
- graemep 2y agoNot using the "WAN" attack if you are using a firewall config that stops that on public wifi. I do not understand how the mDNS entry point works.
- rolph 2y agoi knew there was a reason i blacklist unsolicited/unauthenticated UDP inbound.
- deleted 2y ago